1. Who we are
Rangka.co is operated by:
Operator: GV Engineering Works (M) Sdn Bhd
Company registration number: 201601008901 (1179829-H)
Registered address: No. 6, Jalan Perusahaan 3, Kawasan Perindustrian Batu 20, 48000 Rawang, Selangor, Malaysia
Privacy and data requests: privacy@rangka.co
2. Scope and responsibilities
This policy applies to the Rangka.co website, platform, support interactions, and connected project workflows. For account, website, security, and commercial administration data, Rangka.co determines how and why personal data is handled.
For project information submitted to a company workspace, the Customer generally decides why that information is collected and who may use it. Rangka.co handles it to provide the service on the Customer’s instructions. Users should direct project-specific access or correction questions to their employer or workspace owner first.
3. Personal data we collect
- Account and company data: name, work email, account identifiers, company, role, project assignments, invitation and login information.
- Project and field data: project names, locations, schedules, tasks, progress, daily reports, approvals, comments, messages, photographs, files, voice notes, transcripts, and related metadata.
- Connected-channel data: Telegram identifiers, group or chat identifiers, sender details, message timestamps, and content submitted through a connected channel.
- Usage and technical data: device and browser information, IP address, timestamps, pages and features used, diagnostics, audit events, and security logs.
- Commercial data: selected workspace plan, capacity packages, usage allowances, subscription status, billing currency, invoices, receipts, purchase-order references, Enterprise contacts and support ownership, and limited payment-related information when billing is enabled. Full card details are handled by the payment provider, not stored by Rangka.co.
- Communications: support requests, feedback, survey responses, and other correspondence.
4. Where personal data comes from
We receive data directly from you; from your company, workspace owner, colleagues, or project participants; from connected services such as Telegram; from support conversations handled through Crisp; and automatically from your browser, device, and use of the platform. We may also receive billing and account status from service providers.
5. How and why we use personal data
We use personal data to:
- create and secure accounts and company workspaces;
- deliver project messaging, controls, reports, project schedule views, records, and exports;
- connect authorised communication channels and attribute submitted evidence;
- prepare AI-assisted drafts for human review;
- administer Free and paid plans, subscriptions, usage limits, and payments, including using approximate IP country to assign MYR pricing in Malaysia and USD pricing elsewhere;
- provide support, communicate service changes, and respond to requests;
- where you choose to receive them, send product guidance, re-engagement messages, and relevant plan or upgrade information;
- reconcile subscription state, monitor estimated service cost and margin, detect unusual Free-plan usage or billing failures, protect users, preserve audit integrity, and troubleshoot;
- analyse and improve performance, reliability, accessibility, and product design; and
- comply with law, enforce agreements, and establish or defend legal claims.
Depending on the context, this processing is necessary to provide the requested service, carried out with consent, required by law, or reasonably necessary for security and legitimate business operations without overriding applicable rights.
6. AI-assisted processing
Rangka.co may send relevant project content to contracted AI service providers to transcribe, classify, summarise, extract project details, or prepare draft reports. AI output is not automatically approved. An authorised user must review it before it becomes an approved project record.
We limit AI processing to the information needed for the requested feature and apply contractual and technical controls appropriate to the service. Customers should avoid submitting unrelated sensitive personal data.
8. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal data, including access controls, tenant separation, encrypted transport, managed infrastructure, backups, logging, and restricted administrative access. No system is completely secure, so Customers must also manage memberships, passwords, connected channels, devices, and exports carefully.
9. Retention, recovery and deletion
We retain personal data while needed to operate the workspace, maintain audit integrity, meet legal or contractual obligations, and resolve disputes. Report text and audit metadata remain records; stored project photos and voice notes follow these periods:
- 24 months after a project is completed.
- 90 days after paid access ends.
- 90 days after a storage-reducing downgrade when usage remains over the new allowance; active-project media is protected.
- After 24 months without workspace activity, followed by a 90-day warning period.
- 30 days after a verified intentional deletion request.
When more than one period applies, the later completed-project protection applies. Legal holds pause deletion. Applicable schedules are shown in the account and billing screens.
Deletion remains subject to backup cycles, technical processing time, fraud prevention, legal holds, and required legal or contractual retention. Approved reports, audit history, and supporting evidence may need to be retained, access-restricted, or de-identified. Residual encrypted backup copies are isolated from ordinary use and expire according to backup schedules.
10. Your rights and choices
Subject to applicable law and identity verification, you may ask to access or correct personal data, withdraw consent where processing depends on consent, object to certain direct marketing, or request deletion. Optional product and plan email can be turned off from Account → Notifications or through the unsubscribe link in every such message. This does not turn off security, billing, retention, or other required service notices. Some requests may be limited where information must be retained for security, legal, contractual, evidentiary, or dispute purposes.
For project data controlled by your company, contact the workspace owner or your employer first. You may also contact us at privacy@rangka.co. We may ask for information needed to verify your identity, workspace, and authority before acting.
For a plain-language account of what Rangka records from chat messages, who sees it, and how to dispute or ask for your data, read Your data and Rangka.
12. Updates and contact
We may update this policy when our service, providers, or legal obligations change. We will post the revised effective date and provide reasonable notice of material changes.
For privacy questions, access or correction requests, withdrawal of consent, or data-deletion requests, contact privacy@rangka.co. Legal questions are governed together with our Terms and Conditions.